Published: Mon 28 September 2026
Prepared by: Brandon Sawyer, Vulnerability Analyst
On 27 September 2026, Citrix published security bulletin CTX697096, disclosing eight vulnerabilities (CVE-2026-88771 to CVE-2026-88778) in Citrix NetScaler ADC and NetScaler Gateway. This bulletin focuses on two of them, CVE-2026-88771 and CVE-2026-88772: critical remote code execution (RCE) vulnerabilities that Citrix, the US Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) all confirm were exploited as zero-days before a fix was available. CISA added both to its Known Exploited Vulnerabilities (KEV) catalogue on the same day.
ASD's ACSC has not yet received reports of confirmed exploitation in Australia. However, organisations running NetScaler ADC or NetScaler Gateway should treat patching as an emergency priority and assess appliances for compromise, given the pre-disclosure exploitation.
CVE-2026-88771 is an improper input validation vulnerability (CWE-20) with a CVSSv4.0 base score of 9.5 (Critical). It allows an unauthenticated attacker to execute arbitrary commands. It affects every NetScaler ADC and NetScaler Gateway deployment on a vulnerable version, including the default configuration, with no additional feature required. Because no special configuration is needed, every internet-reachable appliance on an affected build should be considered exposed.
CVE-2026-88772 is a memory overflow vulnerability (CWE-119) with a CVSSv4.0 base score of 9.5 (Critical). It can lead to remote code execution or denial of service when DTLS is configured, and DTLS is enabled by default on VPN virtual servers. As a result, a NetScaler Gateway is affected unless DTLS has been explicitly disabled.
A threat actor needs only network access, not a valid account, to exploit either flaw. Internet-facing Gateway, VPN and AAA virtual servers should be prioritised.
The Citrix bulletin addresses six further NetScaler vulnerabilities, CVE-2026-88773 to CVE-2026-88778. These depend on specific configurations and include HTTP request smuggling, memory overflow and denial of service issues. None had been reported as exploited at the time of writing. Citrix has provided instructions for customers to check whether their device meets the preconditions for each of these configuration-dependent CVEs. Of these, CVE-2026-88778 is fixed by enabling Enhanced ISN Generation rather than by the upgrade alone.
These vulnerabilities are separate from CVE-2026-19490. That authentication bypass was fixed on 19 August 2026 and added to the KEV catalogue on 9 September. Appliances patched for CVE-2026-19490 remain vulnerable unless they run one of the fixed builds listed below.
Discovery and Disclosure Timeline
| Date | Event |
| 26 Sept 2026 | NetScaler administrators report being told by suppliers and security teams to shut appliances down, following a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL). watchTowr publicly warns that multiple unpatched NetScaler RCE vulnerabilities are being exploited after being identified during forensic investigations. |
| 27 Sept 2026 | Citrix publishes security bulletin CTX697096, confirms both vulnerabilities and releases fixed builds. CISA adds CVE-2026-88771 and CVE-2026-88772 to the KEV catalogue. |
| Ongoing | This remains an emerging situation. Organisations should monitor Citrix's security bulletin and NetScaler Console for updated guidance and indicators of compromise as they are published. |
NetScaler ADC and NetScaler Gateway sit at the network edge, handling VPN and remote access, load balancing and user authentication for staff and customers connecting to internal applications. Successful exploitation gives a threat actor unauthenticated code execution on the appliance. That can expose:
Because both vulnerabilities were exploited before a fix existed, patching does not show whether a threat actor gained access first. After a NetScaler zero-day was exploited against Dutch organisations in 2025, NCSC-NL warned that updating alone did not remove the risk, because an attacker could keep access gained before the patch.
Primary Remediation
The primary remediation is to upgrade all NetScaler ADC and NetScaler Gateway appliances to the fixed build for their release line:
| Product | Affected Versions | Fixed Release |
| NetScaler ADC and NetScaler Gateway 14.1 | Before 14.1-73.37 | 14.1-73.37 |
| NetScaler ADC and NetScaler Gateway 13.1 | Before 13.1-64.23 | 13.1-64.23 |
| NetScaler ADC 14.1-FIPS | Before 14.1-73.37 FIPS | 14.1-73.37 FIPS |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | Before 13.1-37.279 | 13.1-37.279 |
Secure Private Access hybrid deployments that use NetScaler instances are also affected. The bulletin covers customer-managed appliances, and Citrix updates its own managed cloud services. The 13.1 fix was released even though that branch reached End of Maintenance on 15 September 2026. Organisations on 13.1 should plan migration to 14.1.
Before upgrading a 13.1 appliance, run show ns variable. If it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop during the upgrade. Also enable Enhanced ISN Generation to address CVE-2026-88778.
Citrix has not published a workaround for either exploited vulnerability, so upgrading is the only way to close the entry point. CISA urges organisations to check for compromise before patching where possible, and to preserve forensic evidence first, because updates may cause a loss of forensic visibility. Evidence collection should therefore come before the upgrade on any internet-facing appliance.
In addition to applying the update, ASD's ACSC recommends that organisations review the preconditions for each of the eight CVEs to understand where their devices may have been vulnerable to exploitation. It also advises organisations to use their internal security assessments and business plans to decide how to prioritise implementing the update. Given confirmed pre-patch exploitation of CVE-2026-88771, which affects all configurations, internet-facing appliances should be at the top of that list.
Compensating Controls
No workaround addresses these vulnerabilities directly. Where an immediate upgrade cannot be completed, the following measures can reduce exposure in the interim:
These measures reduce the attack surface but do not fix the underlying flaws. They also will not remove any persistence a threat actor established before they were applied.
Hardening and Longer-Term Actions
Organisations that identify or cannot rule out compromise should follow Citrix's guidance for suspected compromise. That guidance covers the following steps:
NetScaler logs should also be forwarded to a centralised SIEM so they remain available for retrospective investigation.
Indicators and Log-Based Detection
Citrix has made indicators of compromise (IOCs) available through NetScaler Console. Organisations can run the IOC scan on the Console Security Advisory page, which requires version 14.1-73.36 or later with telemetry enabled, or request the IOCs from Citrix Support. These indicators should be treated as a starting point. Citrix warns that the IOCs do not cover every technique, so a clean result does not prove the appliance is uncompromised.
Recommended Detection and Hunting Activities
MDR customers: Triskele Labs will continue tuning detections and analysing IOCs, as they become publicly available for behaviours consistent with the exploitation of CVE-2026-88771 and CVE-2026-88772 across supported log sources.
Vulnerability Management customers: Environments will be assessed for vulnerable versions of Citrix NetScaler ADC and NetScaler Gateway affected by CVE-2026-88771 and CVE-2026-88772 once detections are made available. Any findings will be communicated through priority channels.
This remains an emerging situation. We urge all organisations running Citrix NetScaler ADC or NetScaler Gateway to stay up to date with information from trusted vendor and government sources as further guidance is published.